The essentials in 30 seconds
- With synthetic payloads, Enforcis runs controlled campaigns on the configured paths and observes how your controls actually behave, scenario by scenario.
- Version 1.0 tests 8 channels: HTTPS, HTTP, DNS, FTP, ICMP, GitHub Gist, Google Drive and DPaste.
- For each scenario tested, you see whether your controls blocked it, detected it without blocking it, or did not detect it, with dated, traceable results.
- Agents in your environment, orchestration in the Enforcis cloud or in your private cloud; 100% on-premises deployment possible, subject to assessment, for critical environments.
What the platform does
Enforcis is an active data exfiltration testing platform. From real Windows and Linux machines, it tries to push synthetic data out through the channels an attacker would use, then records which egress controls (DLP, proxy, firewall, CASB) block it, detect it or let it through.
It does not read your rules. It checks what they do when something actually tries to leave, on the scenarios tested. Replaying after a change matters, because a single agent update or a new exception is enough to reopen a path.
How a campaign runs
- Scope. We define with you the machines, the channels and the synthetic data categories (for example synthetic IBANs or synthetic HR files).
- Exit attempts. The agents try to send the decoys out, channel by channel.
- Three possible states per scenario. Blocked; detected, not blocked; or not detected.
- Dated results. Each scenario tested is recorded with its date and its state, within the scope actually tested. Upcoming versions will add contextual, prioritised recommendations, validated by retest.
- Replay. Upcoming versions will let you schedule periodic replays, or replays triggered by a change, depending on how critical the scope is and how fresh the evidence needs to be.
The 8 channels tested in version 1.0
Scroll the table →
| Channel | Family | Controls usually involved |
|---|---|---|
| HTTPS | Web | Proxy or secure web gateway with TLS inspection, network DLP |
| HTTP | Web | Proxy, network DLP, firewall |
| DNS | Network protocol | Internal resolver, DNS filtering, firewall, detection |
| FTP | Network protocol | Firewall, proxy, network DLP |
| ICMP | Network protocol | Firewall, network detection |
| GitHub Gist | Cloud service (code) | Proxy and TLS inspection, CASB, DLP |
| Google Drive | Cloud service (storage) | CASB, proxy, endpoint DLP |
| DPaste | Paste site | URL filtering, proxy, DLP |
Not covered in version 1.0
To avoid any misunderstanding, here is what Enforcis 1.0 does not replay:
- Removable media (USB) and printing.
- Operational technology (OT) networks.
- Outbound email and mail gateways.
- Native Microsoft 365 locations: Exchange Online, SharePoint, OneDrive and Teams.
Our articles explain how to test these channels yourself, for example email DLP rules or Microsoft Purview™ policies. The platform itself does not run those tests.
Architecture and data handling
- Lightweight agents on Windows or Linux machines, an orchestrator and a console.
- Agents in your environment, orchestration in the Enforcis cloud or in your private cloud; 100% on-premises deployment possible, subject to assessment, for critical environments.
- Upcoming versions will bring SIEM integrations and deployment options that make it possible, in particular, to keep logs and evidence in your environment.
- Test payloads are synthetic; no real customer business data is used as a campaign payload.
- The test destinations (GitHub Gist, Google Drive, DPaste) are accounts controlled by Enforcis, purged after each campaign.
- The scope is defined with you before any campaign in production.
What stays with you, what leaves and the questions we answer during a vendor assessment are on the Security and trust page.
How to get started
- A 30-minute demo on our demo environment, followed from a standard browser.
- A proof of concept in a synthetic environment, without touching production.
- A paid pilot on a limited production scope, with a report and prioritised findings.
Next step
See a campaign in 30 minutes, across the channels covered by the demo scenario.
We show you what gets out, what is detected and what is blocked, on a synthetic environment.
Frequently asked questions
Does Enforcis replace a penetration test?
No. A penetration test shows what an attacker can reach. An exfiltration test shows what can actually get out once the data is reached. The two complement each other.
Which channels does Enforcis not test?
Version 1.0 does not replay removable media (USB), printing, OT networks, outbound email, or native Microsoft 365 locations (Exchange Online, SharePoint, OneDrive, Teams). It tests HTTPS, HTTP, DNS, FTP, ICMP, GitHub Gist, Google Drive and DPaste.
Is it safe to run in production?
Campaigns use synthetic payloads only: no real customer business data is used as a campaign payload, and the scope is defined with you. If you prefer to start without touching production, the proof of concept runs in a synthetic environment.
Where does the data go during a test?
For the cloud channels, the synthetic payloads go to GitHub Gist, Google Drive and DPaste accounts controlled by Enforcis and purged after each campaign. Where findings and logs are kept depends on where the orchestration runs: in the Enforcis cloud, in your private cloud or, subject to assessment, on your premises.
